T09 · Insecure Skill Coding Practices
- Location
lib/modelSelector.js:154- Finding
Arbitrary JavaScript Execution Through Unsafe Configuration Parsing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's multi-agent purpose is coherent, but unsafe configuration parsing and unvalidated path-based writes require review before installation.
Install only if you are comfortable granting this skill control over OpenClaw workspace files and subagent orchestration. Before use, the publisher should remove the eval fallback, validate path-derived identifiers, and replace destructive rm -rf documentation with backup or dry-run workflows.
lib/modelSelector.js:154Arbitrary JavaScript Execution Through Unsafe Configuration Parsing
lib/archiver.js:44Arbitrary Filesystem Writes Through Path Traversal in Workflow and Agent Identifiers
The specific command rm -rf ~/.openclaw/workspace/agents is an unsafe deletion primitive in documentation because it encourages irreversible removal of agent data. In the context of a multi-agent orchestration skill, that directory is likely to contain working state or outputs, so the operational risk is higher than a generic example command.
测试步骤:
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The specific command rm -rf ~/.openclaw/workspace/agents is an unsafe deletion primitive in documentation because it encourages irreversible removal of agent data. In the context of a multi-agent orchestration skill, that directory is likely to contain working state or outputs, so the operational risk is higher than a generic example command.
测试步骤:
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The specific command rm -rf ~/.openclaw/workspace/shared can permanently delete shared project artifacts and coordination data. Since this skill manages multi-agent collaboration, deletion of shared state can affect multiple tasks and lead to broader operational disruption than a single-user cache clear.
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 2. 运行检查
The specific command rm -rf ~/.openclaw/workspace/shared can permanently delete shared project artifacts and coordination data. Since this skill manages multi-agent collaboration, deletion of shared state can affect multiple tasks and lead to broader operational disruption than a single-user cache clear.
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 2. 运行检查
Deleting the profile/configuration file removes local settings and can break or reset agent behavior unexpectedly. While less destructive than recursive directory deletion, it still causes loss of configuration and may be copied verbatim by users following the test procedure.
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 2. 运行检查
多代理 check_env
The document explicitly instructs deletion of ~/.openclaw/workspace/agents using rm -rf. In the context of a multi-agent orchestration skill, that directory likely contains agent state, artifacts, or user work product, so copying the command can cause immediate data loss and disruption.
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The document explicitly instructs deletion of ~/.openclaw/workspace/agents using rm -rf. In the context of a multi-agent orchestration skill, that directory likely contains agent state, artifacts, or user work product, so copying the command can cause immediate data loss and disruption.
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The rm -rf ~/.openclaw/workspace/shared command recursively deletes the shared workspace, which may contain common data used across agents and projects. Because this skill is designed for project collaboration and workflow orchestration, the context makes deletion more dangerous by increasing the likelihood of collateral loss affecting multiple tasks or users.
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
The rm -rf ~/.openclaw/workspace/shared command recursively deletes the shared workspace, which may contain common data used across agents and projects. Because this skill is designed for project collaboration and workflow orchestration, the context makes deletion more dangerous by increasing the likelihood of collateral loss affecting multiple tasks or users.
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
Deleting ~/.openclaw/workspace/.multi-agent-profiles.json can remove configuration or profile state needed for the orchestrator to function correctly. Although narrower than recursive directory deletion, it can still break the environment and cause loss of user-specific setup, especially if executed on a real workspace instead of a throwaway test instance.
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
多代理 check_env
The specific command rm -rf ~/.openclaw/workspace/agents deletes the agents workspace recursively and without confirmation. This is dangerous because it can irreversibly remove agent definitions, generated artifacts, or local state, and users may not understand the blast radius from a brief test snippet.
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The specific command rm -rf ~/.openclaw/workspace/agents deletes the agents workspace recursively and without confirmation. This is dangerous because it can irreversibly remove agent definitions, generated artifacts, or local state, and users may not understand the blast radius from a brief test snippet.
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
The command rm -rf ~/.openclaw/workspace/shared deletes the shared workspace recursively and forcefully. In a multi-agent collaboration system, shared directories are especially sensitive because they may contain outputs from multiple workflows, making the damage broader than a single-user cache reset.
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
The command rm -rf ~/.openclaw/workspace/shared deletes the shared workspace recursively and forcefully. In a multi-agent collaboration system, shared directories are especially sensitive because they may contain outputs from multiple workflows, making the damage broader than a single-user cache reset.
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
The command removes the multi-agent profiles file, which can erase configuration needed to restore agent behavior or access prior state. Although less severe than directory-wide deletion, it is still destructive and undocumented as such in the surrounding text.
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json
# 运行检查
多代理 check_env
The command rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager performs forced recursive removal of the installed skill directory. This can cause accidental loss of local modifications or related artifacts, and in automation-heavy environments destructive install instructions may be executed without sufficient review.
手动升级:
# 1. 删除旧版本
rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager
# 2. 重新安装
clawhub install multi-agent-engine
The command rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager performs forced recursive removal of the installed skill directory. This can cause accidental loss of local modifications or related artifacts, and in automation-heavy environments destructive install instructions may be executed without sufficient review.
手动升级:
# 1. 删除旧版本
rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager
# 2. 重新安装
clawhub install multi-agent-engine
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command, suspicious.dynamic_code_execution